Impact
A heap-based buffer overflow in the core libraries of RTI Connext Professional allows an attacker to overwrite adjacent memory, potentially leading to arbitrary code execution or denial of service. The flaw is classified as CWE-122 and can compromise confidentiality, integrity, and availability if exploited.
Affected Systems
The vulnerability affects RTI Connext Professional from version 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, and from 5.2.3 before 5.2.*.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, but no EPSS score is available, leaving the exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog, so a known exploit is not confirmed. Based on the description, it is inferred that the attack likely occurs over the network through malformed DDS packets sent to the Connext middleware, requiring the target to be reachable from the threat actor's network. The impact could be full compromise of the affected system if an attacker can successfully send crafted data.
OpenCVE Enrichment